Burp Suite User Forum

Create new post

active scan is waiting

Hi, I am working on extension that will send the url to do active scan. I noticed the urls I sent are all in "waiting" and need me to manually click "resume". Is there a way to make it scan without manual...

Last updated: Jun 12, 2018 07:29AM UTC | 5 Agent replies | 7 Community replies | Burp Extensions

Counting the requests from extensions

Hi, I want to ask - when I use some extenders (e.g. Scan Check Builder), when I remove all the Active scan rules, apart from those coming from extensions, and I only have a single extension running. In the session tracer I...

Last updated: Jun 12, 2018 07:04AM UTC | 2 Agent replies | 0 Community replies | Burp Extensions

Extensions class loading

Hello, I was wondering if Burp supports class loading from extensions. What I am looking for is if an extension can be made available as an API and that API's classes be used from other extensions. Does Burp's API...

Last updated: Jun 11, 2018 07:21AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Load an extension headless

Hi, I'm trying to build an easy scanner server, and need to configure Burp to scan in headless mode. As we don't have a graphical interface installed on this server, I have to do all things headless. I would like to...

Last updated: Jun 04, 2018 10:20AM UTC | 4 Agent replies | 4 Community replies | Burp Extensions

How to scan all urls of a webpage from command line.

Hi Team, I have used carbonate to san url from the command line where i can pass one url at a time and it scans the url and gives me the HTML report. Can i scan all the urls of a webpage from command line at a time....

Last updated: May 31, 2018 01:42PM UTC | 3 Agent replies | 2 Community replies | Burp Extensions

Carbonate extender not scanning the url.

Hi , I am trying to run scanner and publish the HTML report from command line. I want the feature to integrate security testing in my devops environment. I have added the carbonate extender. I am running the command :...

Last updated: May 31, 2018 08:04AM UTC | 0 Agent replies | 1 Community replies | Burp Extensions

Attack selector always queues custom attacks

Hello there, I'm trying to figure out how to use the Attack selector extension. After creating a custom attack. I select from the context menu somewhere in Repeater/Proxy/...etc and it goes with status "queued" but...

Last updated: May 25, 2018 07:25AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Can't modify scanner issues context menu

When I try to add a context menu entry to the scanner issues context menu, nothing shows up, it also does not return a InvocationContext when I right click on the scanner issues.

Last updated: May 15, 2018 10:43AM UTC | 2 Agent replies | 2 Community replies | Burp Extensions

sqlipy Hi I am having an issue with both pro and community versions and seek some help please pro

sqlipy Hi I am having an issue with both pro and community versions and seek some help please pro

Last updated: May 10, 2018 01:29PM UTC | 0 Agent replies | 0 Community replies | Burp Extensions

Active scanning sorting features and insertion points fine control.

Hello, With the aim of automating Burp scan in a development cycle, I wish to get the proxy history of a specific Burp project and launch an active scan on each items. To do so I was wondering if you would make the...

Last updated: Apr 26, 2018 08:27AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Burp Extension: Get Focus on Tab after Custom Menu Action

I've written a Burp Extension to add functionality. Everything works great, but I'm having one very stupid issue. When a user Right-Clicks on a Request/Response the context menu allows them to send these requests to my...

Last updated: Apr 16, 2018 04:18PM UTC | 1 Agent replies | 4 Community replies | Burp Extensions

Giving some input parameters to A Burp Suite Extension !..

Hello Burp, I wrote a new Burp Suite extension and I can load it to Burp and work with Burp. But I want to give a parameter to the extension so this extension can use this parameter while its running. How it is possible?...

Last updated: Apr 16, 2018 07:36AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

API function to change Response on the fly

Hi I'm aware of Match and Replace feature to change response on the fly. But is there a way to do it from plugin API ? I'm looking at potential API...

Last updated: Apr 16, 2018 07:16AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Burp Extension

Hello there, I am getting the following exception when I'm trying to log a Jython extension I made, please let me know if anyone has face this :S java.lang.RuntimeException: org.python.core.PyException at...

Last updated: Apr 09, 2018 08:15AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Design new extension - Problem with buildRequest and URL Encode

Hi! I'm new to extending Burp and I wanted to add an active scanner plugin for some injections. When I making the requests with a payload with special characters, for example <script>alert(1)</script>, the request...

Last updated: Apr 05, 2018 02:11PM UTC | 6 Agent replies | 6 Community replies | Burp Extensions

IScannerCheck -- Consolidate Duplicate issues method

My question is about the consolidateDuplicateIssues Method. Currently I am writing an extension that passively scans for certain strings in requests. The problem is that there are multiple requests for each site, and the...

Last updated: Mar 27, 2018 07:05AM UTC | 2 Agent replies | 2 Community replies | Burp Extensions

BurpSmartBuster Not Working

Hello, Whenever I try to use BurpSmartBuster it generates errors and does not work properly. It had worked at some point in the past, but that was at least 6 months ago. I am using Burp Suite Pro 1.7.32, on Windows...

Last updated: Mar 26, 2018 07:15AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

burp collaborator

How to use collaborator and what are settings for to use it? and can any one provide me an example for how it works.

Last updated: Mar 23, 2018 08:59AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

callbacks.makeHttpRequest encode special characters to url encode

Hi! When I making the requests with special characters, for example <>, the request is encoded with "URL encode". How could I send the request without encoding anything? My code is as follows: for(String payload:...

Last updated: Mar 22, 2018 09:09AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

API function to check if URL is in scope?

I have created a custom extension that takes all requests of a certain domain from the sitemap, does some magic on the insertion points and then adds the requests with custom insertion points to the active scanner. I'm...

Last updated: Mar 13, 2018 10:25AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Page 39 of 49

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image